grant-writer
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to process untrusted data from external sources, creating a surface for indirect prompt injection.
- Ingestion points: In Phase 1, the orchestrator extracts information from announcement documents provided via external URLs or files, as well as existing materials like resumes and financial statements.
- Boundary markers: The skill definition does not specify the use of delimiters or instructions for the agent to ignore embedded commands within the ingested documents.
- Capability inventory: The agent team has the ability to create and write to a local directory (
_workspace/) and perform web searches if announcement information is missing. - Sanitization: There is no mention of sanitizing, escaping, or validating the content of external files or web content before it is processed by the agent team.
- [DATA_EXPOSURE]: The skill is designed to handle sensitive organizational and personal data, including financial statements, resumes, and core technology details. While no automated exfiltration behavior is defined in this configuration file, the ingestion of such data into the LLM context represents a significant exposure risk if an indirect prompt injection attack were successful.
Audit Metadata